Cyber insurance

Your systems.
Covered for the bad day.

Ransomware, a hacked inbox, customer records out in the world. Tell Gary how you run IT, compare cyber cover across insurers, and a real broker places the policy.

Gary beside a business owner at a 1970s computer terminal

What it responds to

The mornings cyber cover is for.

Breach response, recovery and liability come with the policy. The ones marked optional you tick in the form, and they are priced in.

Everything’s locked, and there’s a note

Ransomware & cyber extortion · optional

Specialists to respond, and the costs of getting back up, on the terms of the PDS. Talk to the insurer before paying anyone anything.

The invoice with new bank details

Cyber crime & funds-transfer fraud · optional

A convincing email redirects a payment. Whether and how much is covered is set by the policy’s cyber crime section.

Customer records get out

Privacy breach response & liability

Forensics, legal advice, notifying the people affected, and claims from those whose data was exposed.

Nothing will load

Data restoration & system recovery

Rebuilding systems and restoring data after an attack, so the business can run again.

The till stops while you’re down

Cyber business interruption · optional

Lost income while an insured cyber event keeps you offline, for the period the policy sets.

Also on the list

More optional covers

  • Reputational harm & PR
  • Hardware replacement
  • Telephone hacking
  • Regulatory defence
  • PCI fines

Test yourself · 4 minutes

What the insurers look at

The price follows the locks.

The form asks about each of these, and cyber insurers rate on them. Missing one doesn’t shut the door, but a few together with a lot of personal data send the quote to an underwriter.

  • Multi-factor authentication on email and remote access
  • Backups kept off the network, restores tested
  • Critical patches applied within a month
  • Endpoint protection on every device
  • Staff trained to spot phishing
  • A written plan for when something goes wrong

How it works

Three steps. One sitting.

A 1970s rotary telephone

Tell Gary how you run IT

The data you hold, where it lives, and the controls you have in place. Plain English, no jargon test.

A 1970s typewriter

The insurers price it

At the limit and excess you choose, with the optional covers you tick priced in.

A stack of manila folders

A person places it

You pick and pay; a broker places the policy and your documents arrive by email.

Before you start

What the form asks.

Intake sheetabout ten minutes

Your business
what you do, turnover and staff
The data
how many records, and whether you take cards
The systems
where data lives, and who you rely on
The controls
MFA, backups, patching, training
The cover
a limit from $250k to $10M, your excess, the extras
The history
incidents in the last five years, plainly

Give advice for a living too? PI is its own policy.

Worth knowing

The bits people wish they’d read.

Why does the form ask about MFA and backups?

Because they are what cyber insurers rate on first. Controls like multi-factor authentication, off-network backups and prompt patching are asked one by one, and the price responds to them.

Why might I get “referred” instead of a price?

Some combinations go to an underwriter rather than the computer: large volumes of personal records without MFA, remote desktop open to the internet without MFA, a previous insurer declining cyber cover, or activities on the restricted list. A broker comes back to you with the figure.

I run IT for other businesses. Is that different?

Yes. Managed-service and hosting providers carry risk across every client, so the form asks a few more questions about how you manage client systems, and the risk is underwritten differently.

My data’s in the cloud. Isn’t that the provider’s problem?

A cloud provider’s terms generally deal with its own systems, not your losses when your accounts or data are compromised. What a cyber policy responds to is set out in its PDS, which we link beside every price.

What do I have to keep doing once I’m covered?

Keep the controls you described in the proposal, notify the insurer fast when something happens, and don’t pay, admit or settle anything without its consent. Our guide, “Staying on the right side of your cyber policy”, walks through what real wordings say.

Is this advice?

Everything here is general information only. It doesn’t consider your objectives, financial situation or needs. We explain how cyber cover works and show what businesses like yours commonly choose; read the PDS and decide what fits.

Keep reading

On the panel

Multiple insurers. One form.

Every cyber quote names its insurer, links its PDS, and shows what the premium includes and how we’re paid, in writing rather than in the fine print.